Server‐side request forgery (SSRF) - NANDITHA90/PortSwigger-LABS GitHub Wiki
LAB - 1
Basic SSRF against the local server









LAB - 2
Basic SSRF against another back-end system








LAB - 3
Blind SSRF with out-of-band detection






LAB - 4
SSRF with blacklist-based input filter







LAB - 5
SSRF with filter bypass via open redirection vulnerability










LAB - 6
SSRF with whitelist-based input filter











